Executive brief
A security vulnerability in Google Chrome for Android could allow a malicious website to misrepresent its identity or security status. By tricking the browser's user interface, an attacker could potentially deceive users into providing sensitive information or performing unintended actions on a fraudulent page. This issue primarily impacts the visual trust indicators users rely on when browsing on mobile devices.
Technical details
A UI spoofing vulnerability exists in the mobile version of Google Chrome for Android. The flaw stems from an incorrect implementation of security UI components, which can be manipulated by a remote attacker using a specially crafted HTML page. By exploiting this, an attacker can bypass visual security indicators or misrepresent the origin of a page to a user. This requires the victim to visit a malicious website. The issue is resolved in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched